×

SYSTEM AND METHOD FOR PROTECTING A PASSWORD AGAINST BRUTE FORCE ATTACKS

  • US 20080120504A1
  • Filed: 10/31/2006
  • Published: 05/22/2008
  • Est. Priority Date: 10/31/2006
  • Status: Active Grant
First Claim
Patent Images

1. A method for providing authentication information from a client device to an authentication device, the authenticating device being provided with a public key Kpub paired to a private key Kpriv associated with the client device, wherein Kpub and Kpriv are generated at the client device, and Kpriv is stored at the client device in encrypted form EKpriv, wherein Kpriv is encrypted by a key K(P) derived from a password P to provide EKpriv, the method comprising the steps of:

  • receiving an input password P′

    at the client device;

    deriving, using the input password P′

    , a key K(P′

    ), wherein the key K(P′

    ) is derived from the input password P′

    using the same method used to derive the key K(P) from the password P;

    decrypting, using the key K(P′

    ), the encrypted private key EKpriv to provide a signing value;

    digitally signing a message using the signing value; and

    transmitting the message to the authentication device, the authentication device being configured to verify the digitally signed message using the paired public key Kpub.

View all claims
  • 4 Assignments
Timeline View
Assignment View
    ×
    ×